US2016315764A1PendingUtilityA1

Fault detection for systems implementing a block cipher

Assignee: INSIDE SECUREPriority: Apr 23, 2015Filed: Apr 25, 2016Published: Oct 27, 2016
Est. expiryApr 23, 2035(~8.7 yrs left)· nominal 20-yr term from priority
H04L 9/004G06F 11/079G06F 11/0751G06F 11/0736H04L 9/0631
25
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A fault detection method for an encryption/decryption system based on a block cipher comprises the steps of subjecting a state array (CST) to multiple rounds, each round comprising a same series of sequential operations transforming the state array; storing the state of a reference operation (ShiftRows) of a current round as a checkpoint state (CHK); storing the state of the reference operation in the next round as an intermediate state; applying one round of reciprocal operations to the intermediate state, starting from the reciprocal of the reference operation (InvShiftRows); and comparing the result state of said one round of reciprocal operations with the checkpoint state.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An encryption circuit based on a multiple-round block cipher, comprising:
 an encryption accelerator comprising, connected in a ring:
 a substitute-bytes circuit, 
 a shift-rows circuit, 
 a mix-columns circuit, 
 an add round-key circuit, 
 a ciphertext register connected to store an output of the add round-key circuit at the rhythm of a round clock, 
 a first multiplexer connected to insert a plaintext message in the ring in a first round, at an input of the add round-key circuit; 
   a decryption accelerator comprising, connected in series:
 an inverse shift-rows circuit, 
 an inverse substitute-bytes circuit, 
 an add round-key circuit, 
 an inverse mix-columns circuit, and 
 a plaintext register connected to store an output of the inverse mix-columns circuit at the rhythm of the round clock; 
   an intermediate state register connected between an output of the shift-rows circuit and an input of the inverse shift-rows circuit, and clocked by the round clock;   a second multiplexer connected to select an output of the add round-key circuit of the decryption accelerator in the first round, and an output of the plaintext register in the other rounds;   a third multiplexer connected to select the plaintext message in the first round and an output of the intermediate state register in the other rounds;   a checkpoint state register connected to store an output of the third multiplexer at the rhythm of the round clock; and   a fault-detector connected to check equality between an output of the second multiplexer and an output of the checkpoint state register.   
     
     
         2 . The circuit of  claim 1 , wherein:
 a key used by the add round-key circuit of the encryption accelerator is a key generated for a current encryption round;   a key used by the add round-key circuit of the decryption accelerator is two rounds behind the key for the current encryption round;   the second multiplexer operates two rounds behind the current encryption round; and   the output of the checkpoint state register is delayed by one encryption round.   
     
     
         3 . A fault detection method for an encryption system based on a block cipher, comprising the steps of:
 subjecting a state array to multiple rounds, each round comprising sequentially:
 substituting bytes from the content of the state array, 
 shifting rows, 
 mixing columns, 
 adding a round key, 
   writing the add round key result in the state array;   storing the state of the shifting rows operation of a current round as a checkpoint state;   storing the state of the shifting rows operation in the next round as an intermediate state;   applying one round of reciprocal operations to the intermediate state, starting from an inverse shifting rows operation; and   comparing a result state of said one round of reciprocal operations with the checkpoint state.   
     
     
         4 . A fault detection method for a decryption system based on a block cipher, comprising the steps of:
 subjecting a state array to multiple rounds, each round comprising sequentially:
 inverse shifting rows from a content of the state array, 
 inverse substituting bytes, 
 adding a round key, 
 inverse mixing columns; 
   writing the inverse mixing columns result in the state array;   storing the state of the inverse substituting bytes operation of a current round as a checkpoint state;   storing the state of the inverse substituting bytes operation in the next round as an intermediate state;   applying one round of reciprocal operations to the intermediate state, starting from a substituting bytes operation; and   comparing a result state of said one round of reciprocal operations with the checkpoint state.   
     
     
         5 . The method of  claim 3 , comprising the steps of:
 generating and storing a reverse key from a cipher key using key expansions;   applying reciprocal key expansions to the reverse key and comparing the result to the cipher key; and   in each round, expanding a new round key from the cipher key and comparing the last round key to the stored key.   
     
     
         6 . The method of  claim 4 , comprising the steps of:
 generating and storing a reverse key from a cipher key using key expansions;   applying reciprocal key expansions to the reverse key and comparing the result to the cipher key; and   in each round, expanding a new round key from the cipher key and comparing the last round key to the stored key.

Join the waitlist — get patent alerts

Track US2016315764A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.